Skip to content
Client login

Free Audit

Digital marketing

Who really owns your page, and what happens the day you are locked out

A page is an asset almost nobody knows the holder of. The access inventory, the roles, and what is never recovered.

Published on 29 May 2026 — Algeria Agency

The article accompanying this one explains that a page can be lost in ten minutes, and describes what hiding, deleting and blocking actually do. It deals with the surface: what shows, what gets moderated, what remains.

This page deals with what is underneath, and is written nowhere: who holds access, what a role permits exactly, what happens when the person who created it leaves, and what is left when nobody can get in.

This is not a communications subject, it is an ownership subject, and it goes untreated precisely because it does not look like marketing. A page with forty thousand followers is a company asset; in most cases that asset depends on somebody’s personal account.

The article follows the order of the risk: the inventory, the roles, the business account, the advertising account, two-factor authentication, the leaver, the agency, being locked out, and the one part you can keep off the platform.

An asset nobody knows the owner of

Ask the question calmly in any business: who owns the page? The answer is almost always a first name, often somebody no longer there, and it is almost always wrong — because that is not how ownership works here.

A page does not belong to a person the way a file does. It is administered by one or more accounts, and each of those is a personal account, with a person’s name, a personal password and a personal telephone number. The business has no account; it only has people.

That mismatch produces every incident in this category. A business believes it holds an asset, and what it actually holds is a set of dependencies on individuals, some of whom have left, and some of whom have lost access to their own account.

The consequence is that there is little to be done once the problem has arrived. That is the peculiarity of this area: it has no reliable cure, only preventive measures that take half an hour and that nobody takes because they produce nothing visible.

That half hour is the next section, and it is the only genuinely urgent content in this article. The rest explains why.

The access inventory: half an hour, once

Open the list of people with access to the page and read it aloud with somebody else. That is all. The exercise systematically produces at least one surprise, and the surprises are always of the same kinds.

You find, first, people gone for years whose account kept its role because nobody removes access when somebody leaves. You find, second, accounts nobody present recognises — a supplier, an intern, a friend of the founder. And you very often find that the person who should hold the highest role does not.

Note three columns only: the account name, the role, and who that is in real life. The third is the one that matters and the one no interface gives you, because an account is rarely named after the job its owner does.

Then remove what needs removing, in one go, and accept that it is awkward: removing access from somebody still on good terms is done with one sentence — "we are tidying up access, I will add you back if you need it". Doing it two years later, after a disagreement, is a hostile act.

Repeat this reading once a year, on a fixed date, with the same document. It is the only rhythm that holds, and it is enough: access does not change that fast, but it never removes itself.

What a role permits exactly

Roles are not degrees of trust, they are sets of powers, and two of them deserve precise understanding because the difference between them is the only thing protecting you.

The highest role can do everything, including adding and removing other people — therefore including removing you. Every other role can publish, reply, moderate, sometimes spend, but cannot touch the access list. That is the boundary, and it is the only one that really counts.

A simple rule follows: the highest role goes to as few people as possible, and never to somebody outside the business. A supplier does not need it in order to work; they need it only to do what you would not want them to do.

The minimum is not one, however. That is the symmetrical error and it is more common: a single holder means a lost phone, a blocked account or an accident leaves you out permanently. Two people, inside the business, preferably not in the same office.

Finally, check that the second holder knows they are one. It sounds absurd and it is frequent: the role was granted once, the person never used it, they changed phone, and the day they are the last resort they cannot log in either.

The business account: the only real answer

There is a structure above pages, intended for businesses, in which the page becomes an asset held by an organisation rather than by individuals. It is the only structural answer to this article’s problem, and it is very widely ignored by small businesses.

What it changes fits in a sentence: people are given access to the organisation, and the organisation holds the page. Removing somebody becomes an administrative operation on a company account, instead of a negotiation with an individual holding personal power.

It brings two secondary benefits that matter as much. Suppliers’ access there is temporary and revocable without discussion. And the advertising account attaches in the same place, which settles half the situations in the next section.

The time to do it is now, and "now" means while the relationship with everybody involved is good. The migration needs the cooperation of whoever currently holds the highest role; that is a formality today and impossible the day that person is in conflict with you.

The honest cost is that this structure adds a layer of complexity and is poorly documented. Allow an hour with somebody who has done it before, rather than three hours alone trying to understand the interface.

The advertising account is not the page

They are two distinct objects with two distinct access lists, and confusing them produces a particularly painful class of incident: you recover the page and not the advertising history, or the reverse.

The advertising account holds three things that cannot be reconstituted: the campaign history, which feeds the system’s learning; the audiences built up over months; and the payment method, with what that implies for invoicing.

Losing the audiences is the most expensive and the least visible. An audience built over eighteen months of traffic and interaction is not rebuilt in a fortnight: it is rebuilt in eighteen months. A business that changes supplier and creates a blank advertising account starts that accumulation from zero, and nobody tells them.

So the rule is the same as for the page, applied to an object nobody thinks to check: the advertising account is opened in the business’s name, attached to its business account, with the business’s payment method, and contributors are invited into it.

Check this today even if everything is fine, because it has one peculiarity: unlike the page, you never notice you do not hold your advertising account until the day you try to recover it.

Two-factor authentication, and why it changes everything

The great majority of lost pages are not sophisticated intrusions: they are personal accounts whose password was obtained, often through a message imitating the platform and asking you to "verify" something.

Two-factor authentication makes that attack useless, because a stolen password is no longer enough. It is the best-value measure in this whole area: it takes five minutes per person and removes the mechanism responsible for most incidents.

It has to be enabled on every account with access to the page, not only the owner’s. The attacker aims at the weakest link, which is often the least important account — an intern, somebody who posts occasionally — and one access is enough to start.

One practical point matters here: prefer an authenticator application to a text message. A text message depends on your SIM card, and changing a number or losing a card is an ordinary event that, in this configuration, costs you access.

And keep the backup codes somewhere other than the phone that generates the codes. That sentence looks obvious written down; it nonetheless describes the exact situation most people who enabled two-factor correctly are in.

The day somebody leaves

A departure is the moment every problem on this page shows up at once, and it is also the moment nobody thinks about it, because a departure is complicated enough already.

The list is four lines and must exist before the first departure: remove page access, remove advertising account access, check that the associated telephone number is not theirs, and check they do not still hold the highest role somewhere.

The third point is the forgotten one and the most insidious. If an administrator account’s recovery number belongs to somebody who has left, the business depends on them for every future reset, indefinitely, including years later.

Do it on the day of departure and not the following week, not out of distrust but because this kind of task never happens "next week". And do it even when the departure is excellent: the rule protects the person as much as the business, since they stop being responsible for an asset that no longer concerns them.

Finally, plan for the bad departure, because it happens. If the person holds the highest role and refuses to cooperate, you have almost no quick remedy — which is precisely the argument of section 4, and the reason to migrate while everything is fine.

The agency that created your page

This is the commonest case among businesses that outsourced their communications, and it is almost never malicious: somebody created the page from their own account because it was quickest, four years ago, and nobody thought about it again.

The situation is asymmetrical and worth naming clearly. The supplier holds an asset of your business, often without thinking about it, and the relationship works perfectly as long as it works. The problem only appears when one side wants to stop — that is, at the worst possible moment to negotiate.

The request to make is simple and not at all aggressive: that the page be attached to your business account, and the supplier invited into it as a partner. They keep exactly the access they need to work; what changes is who can remove whom.

A serious supplier accepts without discussion, because it is standard and because it protects them too — they stop being responsible for an asset that is not theirs. A refusal, or repeated postponement, is in itself the most useful information you will get about that relationship.

Make the same check for the advertising account, the business listing and any other account opened "for you". The reasoning is identical and the oversight is the same: what was opened in somebody else’s name stays somebody else’s until somebody deals with it.

When you are locked out

It happens anyway, and the order of actions matters because the first hours are the only ones in which some things are still possible.

First, work out which of two situations you are in: nobody can get in, or somebody else has. Those are not the same procedures nor the same urgency, and the second is the only one where speed changes anything, because an intruder starts by removing the other access.

Next, attempt recovery from a usual device and a usual place. That detail is not incidental: these systems assess the plausibility of a request, and an attempt from a computer never used before, on an unusual connection, is treated with more suspicion than the same request from the machine that has logged in a hundred times.

In parallel, gather what proves the business is the business: commercial register entry, an invoice for a service in the same trading name, an email address on the domain. Recovery procedures ask for that kind of element, and looking for them during the procedure makes the procedure fail.

Finally, do not immediately create a new page. It is the natural reflex and it complicates recovering the old one, besides splitting your audience between two objects one of which will end up abandoned. Wait until the recovery route is exhausted, which takes days rather than hours.

What is not recovered

This has to be said plainly because nobody says it: in a proportion of cases the page does not come back. Recovery procedures are automated, they sometimes fail for no comprehensible reason, and there is no person to whom you can explain your case.

What is permanently lost then is the accumulated audience — the followers, the posting history, the reviews and recommendations, and the age of the page, which is not nothing. A recreated page is a new page, whatever the years of activity behind it.

What is not lost, and this is the useful part, is everything you kept elsewhere: your original photographs and videos, your text, your customer list, your contact details. A business that kept its files starts again with material; one that kept nothing starts from zero.

Rebuilding then happens in a precise order: the new page, the announcement of the change on channels you still hold — messaging, the site, physical signage in premises — then gradual reconstitution. Allow months, and accept losing part of the audience for good.

This section is what should persuade somebody to do the section 2 inventory. Prevention costs half an hour; failure costs an asset built over years, and there is no insurance.

What you can keep off the platform

Since the platform can be taken from you, the question becomes: what part of all this can exist elsewhere? The answer is broader than expected, and the work is modest.

Your content, first. Original photographs and videos must live in your own storage, not only online. That is true regardless of any access risk: an uploaded image is a recompressed image, and the original is what lets you reuse it elsewhere.

The conversations, next, as far as possible. A customer who has been writing to you for two years is a relationship that exists on the platform and nowhere else; contact details obtained through those exchanges should be recorded in your own file, with their agreement.

The follower list, on the other hand, cannot be recovered or kept — it is a property of the platform, and it is the point that makes the dependency real. The only counter is migrating part of that audience to a channel you hold: an address list, a number, a community elsewhere.

That last point is substantive work rather than a security measure, and it joins the article on owned content. It is justified anyway, and the risk described here is an additional reason rather than the main one.

What we do, and what we refuse

What we do is bounded. We build the access inventory with you, we set up the business account and attach the page and the advertising account to it, we check two-factor on every account involved, and we write the list of actions for a departure.

We refuse to work on a page where the only access offered to us is the highest role. That role would give us the power to remove you, which we do not need in order to work, and accepting it would create in your business exactly the dependency this article describes. We ask for partner access to an organisation you hold.

We also refuse to create a page, an advertising account or a listing from an account belonging to us, even when it is quicker and even when asked. That is how the situations in section 8 arise, and the fact that there was no intention changes nothing three years later.

And we do not promise to recover a lost page. The procedures are automated, they sometimes fail for no reason, and nobody can promise otherwise — a supplier who claims it is selling something they do not control. There is also a check you can make today without us that is worth all the rest: open your page’s access list and read it aloud with somebody.

Frequently asked questions

How do we find out who really holds our page?

Open the list of people with access and read it aloud with somebody else, noting three columns: the account, the role, and who that is in real life. The third is the one no interface gives you. The exercise systematically produces a surprise — a leaver who kept their role, an account nobody recognises, or an owner who does not hold the highest role.

How many people should hold the highest role?

Two, inside the business, preferably not in the same office. One means a lost phone or a blocked account leaves you out permanently; three or more multiply the entry points. And check the second knows they are one and can still log in — a role granted once and never used is common.

Our agency created the page. Is that a problem?

Yes, even with no bad intent. Ask for the page to be attached to your business account and the supplier invited as a partner: they keep the access they need, what changes is who can remove whom. A serious supplier agrees without discussion; a refusal or repeated postponement is the most useful information you will get about that relationship.

Should we enable two-factor authentication?

Yes, on every account with access and not only the owner’s — the attacker aims at the weakest link. Prefer an authenticator application to a text message, which depends on your SIM card. And keep the backup codes somewhere other than the phone that generates them, which is the exact situation most people are in.

What do we do the day nobody can get in?

First establish which situation: nobody can get in, or somebody else has — only the second is a race. Attempt recovery from a usual device and place, which genuinely counts. Gather the documents proving the business’s identity in advance. And do not create a new page straight away: it complicates recovery and splits the audience.

What if the page is never recovered?

It is a possible outcome worth facing: the procedures are automated and sometimes fail for no reason. Followers, history and page age are permanently lost. What remains is what you kept elsewhere — original content, customer contact details, text. That is precisely why the half-hour inventory is worth it.

Where we come in

The inventory tells you who holds what today. The day the holder stops answering, that inventory becomes an archive document.

  • We walk you through attaching it to the business account, screen by screen.
  • We ask for the lowest role that lets the work happen, and give it back after.
  • We check quarterly that two separate people still hold access.

A page already attached to a business account with two active administrators needs nothing: run the check again in three months.

Read next

Let us talk about your project

A free audit, no commitment: we look at your online presence and tell you what is holding it back.

We measure how this site is used with Google Analytics, to learn which pages actually help. You can stop that measurement at any time from the footer. Cookie policy